Story perspectives
Citrix alerts six NetScaler flaws, urges urgent patches.
7/1/2026
1 of 1
Story summary
- Citrix issued a June 30 2026 bulletin detailing six NetScaler ADC and Gateway flaws with CVSS 6.9-8.8.
- CVE-2026-8451, reported by Aliz Hammond in late March 2026, exploits SAML parsing, while CVE-2026-3055 entered CISA’s KEV catalog after active exploitation was confirmed days later.
- Citrix urged applying the patches and, for appliances lacking HTTP Strict Profiles, setting Http2SmallWndTimeout to 30 seconds, noting the bugs cause memory overflows, unauthenticated file reads, and HTTP/2-based denial-of-service.
